
ISO/IEC 27035 Lead Incident Manager
Course Overview
Information security incidents can disrupt business operations, compromise sensitive information, and damage an organization’s reputation. Effective incident management is essential for detecting threats early, responding efficiently, and recovering quickly.
The ISO/IEC 27035 Lead Incident Manager course provides participants with the competencies required to establish and manage an incident management capability aligned with ISO/IEC 27035. Through practical exercises, case studies, and implementation scenarios, participants will learn how to prepare for incidents, coordinate response teams, conduct investigations, manage communications, and drive continual improvement of incident management processes.
Target Audience
This course is intended for:
- Information security managers
- Cybersecurity professionals
- Incident response team members
- Security Operations Center (SOC) analysts
- IT managers and system administrators
- Risk management professionals
- Business continuity and disaster recovery professionals
- Internal auditors
- Security consultants
- Professionals responsible for implementing or managing an information security incident management program
Learning Objectives
Upon successful completion of this course, participants will be able to:
- Understand the principles and concepts of ISO/IEC 27035.
- Explain the information security incident management lifecycle.
- Establish and implement an incident management framework.
- Prepare organizations for effective incident response.
- Detect, report, assess, and classify information security incidents.
- Coordinate incident response and recovery activities.
- Conduct post-incident analysis and implement lessons learned.
- Monitor and continually improve the incident management process.
- Prepare for the PECB ISO/IEC 27035 Lead Incident Manager certification examination.
Duration
5 Days (Four days of instructor-led training followed by the certification examination on Day 5.)
Classroom
Participants attend instructor-led classroom sessions that combine lectures, discussions, practical exercises, workshops, and case studies to develop the skills needed to effectively manage information security incidents.
Certification
After successfully passing the examination and meeting the applicable certification requirements, participants may apply for the:
PECB Certified ISO/IEC 27035 Lead Incident Manager
The certification demonstrates that the holder has the knowledge and competence to establish, implement, and manage an information security incident management program based on ISO/IEC 27035.
Course Agenda
Day 1: Introduction to ISO/IEC 27035 and Incident Management
- Course objectives and structure
- Overview of ISO/IEC 27035
- Principles of information security incident management
- Incident management framework
- Roles and responsibilities
- Organizational preparedness
Day 2: Incident Detection and Reporting
- Incident identification
- Event monitoring
- Incident reporting procedures
- Incident assessment and classification
- Evidence collection and preservation
- Communication and escalation
Day 3: Incident Response and Recovery
- Incident response planning
- Containment strategies
- Eradication and recovery
- Coordination with stakeholders
- Crisis communication
- Business continuity considerations
Day 4: Post-Incident Activities and Continual Improvement
- Post-incident review
- Root cause analysis
- Lessons learned
- Incident metrics and reporting
- Continual improvement
- Course review and exam preparation
Day 5: Certification Examination
- PECB ISO/IEC 27035 Lead Incident Manager Certification Examination
Exam Duration
- Exam Duration: 3 hours
- Exam Format: Closed-book examination consisting of multiple-choice and scenario-based questions.
- Passing Score: Determined by PECB in accordance with its certification policies.
Successful candidates who meet PECB’s experience and certification requirements may apply for the PECB Certified ISO/IEC 27035 Lead Incident Manager credential.
